Description
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
Remediation
References
Related Vulnerabilities
PHP Resource Management Errors Vulnerability (CVE-2012-0781)
WordPress Plugin XforWooCommerce Security Bypass (1.6.4)
Jetty Integer Overflow or Wraparound Vulnerability (CVE-2017-7657)
Claroline Other Vulnerability (CVE-2006-2868)
WordPress Plugin Codestyling Localization 'name' Parameter Cross-Site Scripting (1.99.19)